For example, non-minified bootstrap.js is more than that. Just as a data point.
This will break a bunch of the web. I'll be curious to see how this gets worked out as the work progresses.
For example, non-minified bootstrap.js is more than that. Just as a data point.
This will break a bunch of the web. I'll be curious to see how this gets worked out as the work progresses.
The restrictions are wire size. `bootstrap.min.js` is ~10KiB on the wire, which means it comfortably fits (as do jQuery, most analytics packages, etc.).
That said, the prototype does break a lot of the web, but that's not a crisis. The intent isn't to have this rolled out everywhere against unwitting content, but rather (like TLS), to let developers opt-in to a single set of rules when they see value. There are also places (e.g. PWAs) where the browser-imposed quality bar needs to be high. Blocking PWA install for sites that don't send the opt-in header seems like a reasonable place to start.
Luxon, I believe, is a similar story.